Outlook will block two Windows app package formats in November
Microsoft is adding .msix and .msixbundle Windows application packages to Outlook’s blocked attachment list, aiming to reduce the risk of users installing malicious software. The change applies to New Outlook for Windows and Outlook on the Web in Exchange Online, where affected users will be unable to open or download these attachments by default.
The rollout is scheduled for early to mid-November 2026. Administrators who need to allow the file types can add them to the AllowedFileTypes property of the relevant OwaMailboxPolicy. Outlook already blocks some other file types, including .py, .ps1 and .cab; Microsoft also disabled the ms-appinstaller protocol handler by default in December 2023 after attackers exploited it to distribute malware.
- Outlook will block .msix and .msixbundle attachments by default.
- The change is due in early to mid-November 2026.
- Administrators can allow the file types through mailbox policy.
New here? Start with this
.msix and .msixbundle files are packages used to install modern Windows applications. These file formats have become the standard way that software developers distribute new apps for Windows.
Microsoft views these file formats as potential security risks when sent by email, as malicious actors could disguise harmful software within them to trick users into installing it. To reduce this threat, the company is now preventing Outlook from allowing users to download or open these attachments by default.
The change will affect anyone using the newer version of Outlook on a Windows computer, or those accessing Outlook through a web browser. System administrators can restore access to these files if their organisation has a legitimate need for them.
Both sides, in good faith
The strongest fair case each way — we don't pick a winner.
The case for
Security must be the priority, particularly because .msix and .msixbundle files are executable packages that can deliver malware directly into users' systems. Users frequently lack the expertise to evaluate whether an attachment is genuinely legitimate, and clicking on what appears to be a standard application installer is a common attack vector. Microsoft has already successfully blocked comparable formats like .py, .ps1, and .cab files, and administrators who have genuine business needs to distribute .msix packages can easily whitelist them through group policies—so legitimate workflows remain possible whilst casual users gain essential protection.
The case against
Blocking .msix and .msixbundle formats penalises legitimate business processes and contradicts Microsoft's own strategy of promoting .msix as the modern standard for Windows application distribution. Many organisations and software vendors legitimately distribute applications through these formats, and now their users will face download failures and frustration even when IT administrators intend to allow these files. The security benefit is likely overstated, as sophisticated attackers will find alternative distribution methods whilst standard business workflows suffer; this is essentially a blunt instrument that inconveniences everyone rather than effectively stopping determined threats.
Read the full article at the source →
Originally published by The Register as “Microsoft extends the Outlook naughty step with two more file types”.